Firewall Wizards mailing list archives
Re: frame relay...
From: Arjan Vos <arjan_vos () ins com>
Date: Wed, 24 Nov 1999 09:07:08 +0100
Hi, "R. DuFresne" wrote:
Folks, I'm wondering about the security of frame realy connections. How easy would it be for others to snarf up traffic from a frame realy cloud?
Not very easy. Might be possible if you are doing reverse ARP in a point to multipoint situation. But most security problems are caused by misconfigurations (e.g. misconfigures access lists on FR access routers).
Has there ever been a report of a 'hacked' system via a frame realy connection?
Not that I am aware of. If attempts are made this will probably end up in a DoS. Anyhow, I don't think there is a significant risk with FR. There _is_ a risk, but a small one, and it's not bigger than risks associated with leased lines.
Do tools exist that can accomplish this? Or would it at least require a fullend sniffer box with the proper modules to snarf such packets?
Installing a sniffer requires physical installation of the sniffer at either the client side or provider's site. Might be easier than most people want to believe, but it still requires in-depth knowledge of the provider's set up. Another possible compromise might occur through rerouting traffic. This is also very unlikely, as the attacker also needs a pretty high level of insider knowledge. Changes need to be done at provider's switches, client IP addresses, etc. This would probably result in collusion and DoS. Also, there is a high risk for the attacker as the circuit would point to a physical location and the attacker. You have to look at the access sides of the FR cloud. Are multiple clients connected to the FR access router? Is traffic seperated through access lists? If so, an attacker might try to get to the other site through the FR cloud, but not by hacking the FR cloud itself. These are your regular security issues we deal with everyday. I have had a client whose traffic was sent over a piece of shared LAN at the provider's site (together with traffic from other provider client's who happen to share the FR access routers a well). And on that same piece of LAN remote access boxes were installed to facilitate provider's operators to dial in and do troubleshooting of FR access routers. But, again, this is not FR related.
Thanks, heading to the books to look about myself some too, Ron DuFresne
Gr. Arjan -- Lucent Technologies NetCare Professional Services Hogehilweg 8 1101 CC Amsterdam The Netherlands +31 (0)6 22999776 (mobile) +31 (0)20 8802899 (fax) avos () lucent com (e-mail)
Current thread:
- frame relay... R. DuFresne (Nov 23)
- Re: frame relay... Arjan Vos (Nov 28)
- <Possible follow-ups>
- RE: frame relay... Sink, Douglas D (Doug), BNSVC (Nov 30)
